masscan
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill provides numerous examples and a shell script for running network utility commands including
masscanandnmap. These commands facilitate scanning IP ranges and services. The skill also makes use of standard text-processing utilities likegrep,awk, andjqto parse scan results. - [INDIRECT_PROMPT_INJECTION]: The skill defines workflows that involve the agent reading and processing data generated by masscan (e.g., service banners retrieved via the
--bannersflag and port scan outputs). If a scanned target serves malicious strings in its banners, it could potentially influence the agent's behavior during data analysis. - Ingestion points: Data enters the context from external sources via
results.json,masscan.out, and target files likehosts.txtas described inSKILL.mdandreferences/tuning.md. - Boundary markers: No explicit boundary markers or instruction-ignoring delimiters are specified for the processing of these external output files.
- Capability inventory: The skill utilizes shell execution for port scanning, service identification, and file creation/modification.
- Sanitization: The provided documentation and scripts do not include steps to sanitize or filter service banners or other network-sourced data before they are processed by the agent or piped into other tools.
Audit Metadata